Sunday, May 06, 2007

Our Public "Private" Lives

On October 15, 1999, in Nashua, New Hampshire, Liam Youens murdered Amy Boyer and then killed himself.

Youens shot twenty-year old Amy as she left the dental office where she was working while attending college and then turned the gun on himself.


Why did he kill her? For some reason, Youens became obsessed with Amy in high school, after seeing her on a bus.

The two apparently never even had a conversation, but over the years Liam Youens became more and more obsessed with Amy Bouer. For several years he maintained a website – http://www.amyboyer.com -- on which he rambled about his obsession with her, and with her death. The site included comments like “I have always lusted for the death of Amy” and “Why am I killing her”, repeated three times.


Youens also stalked Amy by staking out her parents’ home at night. He seems to have finally decided to ambush Amy as she left work, but didn’t know where that was. To find out, he contacted an “Internet-based investigation and information service known as Docusearch.com.” Remsburg v. Docusearch, Inc., 149 N.H. 148, 816 A.2d 1001 (New Hampshire Supreme Court 2003). Youens placed several orders with Docusearch for, among other things, Amy’s birth date and Social Security number. After placing several requests, he finally got the address of the orthodontist for whom she was working. Soon afterward, he drove there and killed her.

Since Youens killed himself, as well, there was no homicide prosecution. Amy’s mother sought a type of redress by suing the only available participant in her daugher’s death: Docusearch, Inc. Helen Remsburg filed a federal lawsuit against the company in which she asserted several civil, tort causes of action – one of which was invasion of privacy. Remsburg v. Docusearch, Inc., 2002 WL 844403 (U.S. District Court for the District of New Hampshire 2002).

In this claim, Mrs. Remsburg argued that Amy “had a reasonable expectation of privacy in her personal information, including . . . her work address.” New Hampshire’s law in this area was not clear, so the federal district court certified the question of whether one has an actionable expectation of privacy in their work address to the New Hampshire Supreme Court. This is a process federal courts use when they need to apply state law in a suit before them; the federal court essentially asks the state court to decide what the law is.


This is what the New Hampshire Supreme Court did. It actually disposed of the workplace privacy question rather summarily:
We must first establish whether a work address is something secret, secluded or private about the plaintiff. . . .

In most cases, a person works in a public place. `On the public street, or in any other public place, [a person] has no legal right to be alone.’ W. Page Keeton et al., Prosser and Keeton on the Law of Torts § 117, at 855 (5th ed.1984).

A person's employment, where he lives, and where he works are exposures which we all must suffer. We have no reasonable expectation of privacy as to our identity or as to where we live or work. Our commuting to and from where we live and work is not done clandestinely and each place provides a facet of our total identity.

Webb v. City of Shreveport, 371 So.2d 316, 319 (La.Ct.App.1979). Thus, where a person's work address is readily observable by members of the public, the address cannot be private and no . . . action can be maintained.

Remsburg v. Docusearch, Inc., (New Hampshire Supreme Court 2003).

The same result applies under the Fourth Amendment, which limits what government agents can and can’t do in investigating crime. There’s a long line of cases holding that our movements in public, which can be observed by anyone, are not private.

And since what occurs in public places is not private under the Fourth Amendment (or for civil tort law governing invasions of privacy), the government can install cameras to record our movements in public without obtaining a warrant. As a Delaware court noted, “all courts who have considered the Fourth Amendment in the context of cameras aimed at public streets or other areas frequented by large groups of people have determined that an expectation of privacy in these areas is unreasonable.” State v. Bailey, 2004 WL 2914320 (Delaware Superior Court 2004).

Several courts have also found that there is no Fourth Amendment violation when the government puts video cameras on telephone poles and aims them at someone’s home in order to monitor what goes on outside the home. In United States v. Jackson, 213 F.3d 1269 (10th Cir. 2000), for example, federal agents did precisely this and the Tenth Circuit Court of Appeals held that there was no Fourth Amendment issue:

[T]he video cameras installed on the telephone poles were incapable of viewing inside the houses, and were capable of observing only what any passerby would easily have been able to observe. Thus, Ms. Jackson had no reasonable expectation of privacy that was intruded upon by the video cameras. Therefore, we conclude Ms. Jackson's rights under the Fourth Amendment were not implicated, and there was no need for the police officers to obtain a search warrant before installing and utilizing the video cameras.

Some courts suggest it would violate the Fourth Amendment to use them to look inside the home, though I’d argue there is no violation even then if the camera is only looking through an unshielded window, i.e., a window with no shades or curtains to conceal what goes on inside.

I actually agree with all of these courts, as long as the observations of someone’s home or activities are limited to what a human being could observe by following them (to work, say) or by standing in a particular, public place (on the sidewalk in front of or across the street from Ms. Jackson’s home, say). If and when we start encountering technology that lets government agents and stalkers spy on us in new and really intrusive ways (by looking through the walls of our home, for example), I’d say these cases don’t apply.

But that’s not what I wanted to talk about in this post. What I want to talk about is the residual issue that bothers me in these cases: the collection and retention of data about our lives.

Simply observing what we do in public spaces is nothing new. We have been observing each other, often minutely, since humans began living in social groupings. We are used to this, we intuitively understand the contours and consequences of this type of routine observation and accommodate ourselves accordingly.

It seems to me, though, that capturing and retaining the precise details of our activities, even in public, adds a dimension that has never been present before. The installation of cameras on public streets and in other public places, coupled with the increasing use and pervasiveness of embedded technologies like RFID chips will make it possible to track and record essentially every aspect of our “public” lives. Who, you ask, will be doing this tracking and recordation – the government?

Well, in some instances (as with Ms. Jackson), it will be the government, but for the most part it will be done by private entities – businesses who want to familiarize themselves without tastes and habit so they can more successfully pitch their products to us. (Think of the mobile advertisements in the film “Minority Report,” if you’ve see it.) Much of this tracking and recordation will involve our online activities, as it already does, but that, too, is outside the scope of the Fourth Amendment and comparable civil privacy rights.

I’m not sure what this new dimension is – whether it implicates privacy or something else. I can see the argument that it constitutes an incremental infringement on privacy because of the accuracy and retention of the data being collected. When I used to work in Chicago, I took a commuter train from Evanston to the Loop five days a week (and sometimes on Saturdays). I’d tend to see familiar faces on the train, just because the same people usually rode to and from work at basically the same times. I might have been able to pick some of those faces out of a crowd, or out of a police photo lineup if I’d been asked, but that’s probably the most I could have done. I would never have been able to identify precise physical characteristics (height, weight, eye color, etc.) or even clothes they’d worn, perhaps over and over.

In other words, I would have observed all that information about them, on some level, but my observations would have been sloppy (you basic vague impression of a person) and transient (quickly forgetting what I’d seen in the press of dealing with my own life). With surveillance cameras and RFID chips in clothing and train passes, every aspect of every commuter’s appearance, schedule (took the 7:45 a.m. train X number of times in May, took the 8:15 a.m. train twice that month) and habits (purchased bottled water at the kiosk in the train station on Monday evening, had two beers at the bar in the station on Friday) will be recorded and retained. How long will it be retained? Well, I know that surveillance data is frequently discarded or overwritten, but that’s out of economy, not necessity.

We can, and will, store immense quantities of digital data, which means all of this mundane information about our lives can be available . . . to whomever, for whatever reasons. If it is held by commercial entities, which is the most likely scenario, anyone from the government to a Liam Youens can gain access to the specific details of our lives by requesting them and paying a fee.

I don’t know if it’s privacy or something else, but I can’t help feeling that we lose “something” when the “public” details of our lives are archived and available to whomever, or whatever, wants to rummage through them.

Friday, May 04, 2007

The Government Made Me Do It . . .


I’m often asked why people caught in online stings – like the men in the “To Catch a Predator” shows – can’t raise entrapment as a defense.

Everyone seems to have heard about the defense . . . and those caught in these stings are, in a literal sense, “entrapped.”

The government sets up a fake operation and they fall for it.

In the online predator cases, the government fabricates the whole thing: the existence of a child, the email chats with that child and the premise that the adult male correspondent is going to be meeting that child for the purposes of having a sexual liaison.


Notwithstanding all that, those caught in stings like the “To Catch a Predator” operation will not be able to use entrapment as a defense because U.S. law, anyway, is very parsimonious in allowing people to raise this defense. To illustrate how and what that is, I’m going to use my favorite online entrapment case: United States v. Poehlman, 217 F.3d 692 (9th Circuit Court of Appeals 2000).

According to the court, Mark Poehlman graduated from high school and joined the “Air Force, where he remained for nearly 17 years. Eventually he got married and had two children. When Poehlman admitted to his wife that he couldn't control his compulsion to cross-dress, she divorced him. So did the Air Force, which forced him into early retirement, albeit with an honorable discharge.” U.S. v. Poehlman, supra. Poehlman was a foot fetishist, as well as a cross-dresser. U.S. v. Poehlman, supra.

Losing his wife, his children and his career “left Poehlman lonely and depressed. He began trawling Internet “alternative lifestyle” discussion groups in an effort to find a suitable companion.” U.S. v. Poehlman, supra. When he disclosed his interest in cross-dressing and foot-fetishism, he was met “with strong rebukes.” U.S. v. Poehlman, supra.

He finally “got a positive reaction from a woman named Sharon. Poehlman started his correspondence with Sharon when he responded to an ad in which she indicated that she was looking for someone who understood her family's `unique needs’ and preferred servicemen. Poehlman answered the ad and indicated that he `was looking for a long-term relationship leading to marriage,’ `didn't mind children,’ and had unique needs too.’” U.S. v. Poehlman, supra.

“Sharon,” who was actually an FBI agent, responded positively to Poehlman’s email, and told him she was looking for someone who could “help” with “the special education” of her children. Poehlman responded by saying he “had strong family values” and would treat her children as his own. “Sharon” wrote back saying she was looking for a “`special man teacher’” for her children, and for him to write back if he understood and was interested. U.S. v. Poehlman, supra. “Poehlman replied by expressing uncertainty as to what Sharon meant by special man teacher. He noted that he would teach the children `proper morals and give support to them where it is needed’ . . . and he reiterated his interest in Sharon.” U.S. v. Poehlman, supra.

That, of course, is not what “Sharon” wanted to hear, because Poelhman had gotten involved in an online sting effort. Over the next “six months and scores of e-mails,” the agent posing as “Sharon” worked on Poehlman, making it clear that she expected him to introduce her three fictive daughters – “Karen, aged 7, Bonnie, aged 10, and Abby, aged 12” – to varied types of sexual activity. U.S. v. Poehlman, supra. He ultimately agreed, apparently because introducing the children to sex was held out as a quid pro quo for his having a relationship with “Sharon.” U.S. v. Poehlman, supra.

Poehlman traveled from Florida to California, where he was to begin their instruction, but was arrested by FBI agents and local law enforcement officers. He was convicted of crossing state lines to have sex with a minor in violation of 18 U.S. Code section 2423(b) and sentenced to 121 months.

On appeal, he raised entrapment as his defense. U.S. v. Poehlman, supra. In its opinion, the Ninth Circuit Court of Appeals explained what he had to establish to win on this issue:
When entrapment is . . . raised, the trier of fact [i.e., the jury] must answer two related questions: First, did government agents induce the defendant to commit the crime? And, second, was the defendant predisposed? . . . . [T[he government induces a crime when it creates a special incentive for the defendant to commit the crime. This incentive can consist of anything that materially alters the balance of risks and rewards bearing on defendant's decision whether to commit the offense, so as to increase the likelihood that he will engage in the particular criminal conduct. Even if the government induces the crime, however, defendant can still be convicted if the trier of fact determines that he was predisposed to commit the offense. Predisposition . . . is the defendant's willingness to commit the offense prior to being contacted by government agents, coupled with the wherewithal to do so.

U.S. v. Poehlman, supra.

This, then, is why stings, including the “To Catch a Predator” stings, work. In setting up a sting, the government’s whole purpose is to induce somone who ultimately becomes a defendant to commit (or attempt to commit, in some stings) the crime for which he is charged. That is not a problem as long as the government can prove that he was predisposed to commit the crime. We see this in the “To Catch a Predator” and other, similar online stings: The government merely creates the opportunity for someone to embark on the commission of a crime, such as traveling to have sex with what the person believes is a minor with whom he has corresponded online. As long as the government’s role is purely passive – as long as it is limited, basically, to creating the opportunity for someone to act on their own, evil impulses – the government will not be deemed to have entrapped the person into the commission of a crime.

The Poehlman case is one of the relatively few instances in which entrapment worked. The Ninth Circuit found, first, that the government had inducted him to commit the crime of which he was convicted: “The government . . . played on Poehlman's obvious need for an adult relationship, for acceptance of his sexual proclivities and for a family, to draw him ever deeper into a sexual fantasy world involving these imaginary girls.” U.S. v. Poehlman, supra.

That, though, is not what makes this case unusual; it is not uncommon for courts to find that the government induced someone to commit a crime since, as I noted above, this is the whole purpose of sting operations, online or not. What makes this an unusual entrapment case is that the court also found that Poehlman had not been predisposed to the commission of the crime: “Having carefully combed the record for any evidence that Poehlman was predisposed to commit the offense of which he was convicted, we find none. To the extent the jury might have found that Poehlman was predisposed to commit the offense, that finding cannot be sustained.” U.S. v. Poehlman, supra. (He apparently argued entrapment at trial, but failed to convince the jury; the Ninth Circuit reversed the conviction because it found that the jury should have accepted his entrapment defense.)

The Ninth Circuit ended its opinion by essentially scolding the government:

`When the Government's quest for convictions leads to the apprehension of an otherwise law-abiding citizen who, if left to his own devices, likely would have never run afoul of the law, the courts should intervene.’ [Jacobson v. United States, 503 U.S. 540 (U.S. Supreme Court 1992). . . . Poehlman is such a citizen. Prior to his unfortunate encounter with Sharon, he was on a quest for an adult relationship with a woman who would . . . accept his proclivities, which did not include sex with children. There is surely enough real crime in our society that it is unnecessary for our law enforcement officials to spend months luring an obviously lonely and confused individual to cross the line between fantasy and criminality.

U.S. v. Poehlman, supra.

Sunday, April 29, 2007

Confidence

Confidence: “n.That which is confided, a secret.”

I have an article coming out in the Mississippi Law Journal in which I analyze whether we should criminalize defamation as a way of controlling certain kinds of “problematic” speech online.

By “problematic” I mean cases like the one in Wisconsin in which the fired employee retaliated by using his former boss’ name, address and phone number in a posting he added to “Sex on the Side,” a website for married women who are looking for “action on the side.”

That Iwas a clever, nasty way to cause this woman a lot of grief.


It's also a good example of the kind of thing defamation law COULD be used to discourage because this incident has all the basic elements of defamation: a false statement, published intentionally that has the effect of holding the victim up to ridicule and/or damaging her reputation. Defamation has generally either not been criminalized in this country or, if it is criminalized in a state, tends to be a very minor crime that is seldom, if ever, prosecuted.

But I don’t want to talk about defamation here. I want to talk about a different, residual category of “harm” I encountered in researching the online defamation issue. This type of “harm” results when someone (Person A) posts ostensibly “private” information about another person (Person B).

A good example of the alleged infliction of this type of “harm” came in the Jessica Cutler-Robert Steinbuch case. The two Congressional staffers were lovers for a time. Cutler, without Steinbuch’s knowledge or consent, posted details of their sexual encounters online in her blog. The postings were later picked up by another blog and circulated widely. Steinbuch sued Cutler for “describing in graphic detail the intimate amorous and sexual relationship between Cutler and” himself. His complaint said that her “outrageous actions, setting before anyone in the world with access to the Internet intimate and private facts regarding [Steinbuch], constituted a gross invasion of his privacy, subjecting him to humiliation and anguish beyond that which any reasonable person should be expected to bear in a decent and civilized society.”

I’m perfectly willing to concede that the postings caused Steinbuch humiliation and anguish, both in excess of what a reasonable person would want to endure. My issue lies with the nature of his complaint against Cutler.

This isn’t a defamation case, a libel or slander case, because he doesn’t say that what she posted was untrue. His complaint, then, lies not with what she said but with the fact that she said it – that she “published” it to other people in a very public way. And that’s the issue I want to talk about, the residual issue that cropped up when I was researching the evolving, morphing phenomenon of online defamation.

Historically, defamation law has protected people from “harm” by discouraging others from (i) intentionally (ii) publishing (iii) false information about them that (iv) is calculated to cause them “harm” by damaging their reputation or holding them up to ridicule. For all intents and purposes, I think we can fold “ridicule” into damage to one’s reputation, so I won’t break those “harms” out into different categories.

The rationale the law has used for sanctioning defamatory material falls into two categories: Civil law allows people to seek monetary damages for the publication of defamatory material, on the premise that the compensation redresses the “harm” done to them. Criminal law historically imposed criminal sanctions on people who published defamatory material because its goal was prevent people from doing this and thereby discourage what the law calls “self-help”, i.e., defamed people taking the law into their own hands. This used to be a major concern back in the days of dueling, but this rationale has pretty much dropped out of modern defamation law, so the remaining rationale for both civil and criminal defamation is the damage to one’s reputation.


The Steinbuch case and similar cases in which someone publishes true information about another person can also damage that person’s reputation, but modern defamation law, anyway, would not see that as defamation because, as I noted above, the material is not false. Here, the damage to someone’s reputation results not from their being portrayed in a “false light”, but from information leakage. As everyone who’s ever taken a sociology course knows, we all play roles – we present one “face” to a certain group of people and a very different “face” to other people, or to another person.

We have historically been able to do this because we have been able to exert a fair degree of control over the segregation of personal (and professional) information we rely on to support these disparate roles. Assume, for example, John Doe: a Certified Public Accountant, a deacon in his Methodist church, a coach for his son’s Little League team, a husband and an habituĂ© of Sado-Masochistic clubs, He plays a different role for each activity . . . in effect, has a different “self” for each activity. His ability to segregate those selves depends on his ability to parse the relevant information out among the roles and among the people who experience him in these different roles. And because some of the roles are not inconsistent, the information leakage issue will only become an issue for a certain role or certain roles; in this example, the leakage issue would arise with regard to his recreational S-M activities.

In the real-world, we have always been able to manage this kind of information segregation pretty satisfactorily. Those who know us in our more discreditable roles are unlikely to be people who interact with those who known us in our more “public,” more conventional roles, so that helps sustain the information segregation. Those who know us in these roles may gossip about us, but that will generally have limited circulation in the real, physical world; the gossip will be shared with people who know each other, and since they probably do not participate in the aspects of our lives in which we play more creditable roles, the segregation holds. Information leaking issues can arise, of course, when someone we know from a more discreditable aspect of our lives either directly shared information about that aspect with our families, our co-workers or others whom we interact with in our more creditable roles. This results in some information leakage . . but for those of us, the vast majority of us, who are NOT celebrities, the leakage tends to be limited in scope. That means the damage will also be limited in scope.

Cyberspace changes all this. To paraphrase Louis Brandeis and Charles Warren, who wrote a law review article on invasions of privacy over a century ago, today “what is whispered in the closet” can now be broadcast to the world . . . over and over and over.

That is the Steinbuch problem . . . the information leakage problem. And it is a problem. We trust people. We have to trust people, whether we are being our creditable or our less-than-creditable selves. We realize at some level that people can betray us, but we do not expect them to do so. Like Steinbuch, we are hurt and embarrassed when this happens.

Is this a legal issue? Should this be a legal issue? By that, I mean should the law step in and create a new crime, a new civil cause of action or both to provide mechanisms by which those who betray confidences can be sanctioned? The goal of such innovations would be to discourage people from betraying confidences.

You may disagree, but I do not see how we can do that. When we have affairs, when we go to S-M clubs, when we do other things we would prefer not to have broadcast to the world, we know that can happen. We know we are relying on that most fragile of things: trust . . . confidence that others will not betray us.

How can we prosecute people (I tend to default to the criminal solution) for betraying us? We prosecute people for betraying their country, but that’s different, if only because it is an indirect path toward death, injury, destruction and other real, physical “harms.” When someone betrays us, we suffer a “harm,” a real “harm” . . . but it primarily a psychic “harm.” Criminal law, anyway, has, and is, loath to sanction people for inflicting psychic “harm” on each other. If we began to do that, where would we stop? Would it become a crime to gossip about others . . . about how they dress? How they look? How much they earn? How ugly their dog is? How tacky their apartment is? . . . and so on and so on.

We could try creating a civil cause of action allowing someone to recover damages for the infliction of this type of psychic “harm,” but there are several problems with doing that. One is that the number of lawsuits would very quickly overwhelm the current court system and any court system we’d care to design. The other is that most of the people who would be sued are what the law calls judgment-proof; that is, they don’t have enough assets to pay a judgment or even to pay the other side’s attorneys’ fees.

Law does not seem a good solution. I wonder, then, where all this will take us. Maybe we will become so inured to the “outing” of various aspects of people’s lives that we will lose interest in it. . . .

Friday, April 13, 2007

Snuff Online

A Friday the 13th topic: snuff films

Snuff films, as you may know, are films that show someone being murdered. Unlike video that inadvertently captures a murder, a snuff film is made deliberately; the murder is the purpose and the centerpiece of the film.

Some definitions say a snuff film has to be made for profit; for my purposes here, a profit motive is irrelevant.

What I want to analyze is the legality, or illegality, of “publishing” a snuff film online.


You may have read about the video recently posted to YouTube: It showed a man tied to a chair being beaten and interrogated about killings he eventually admits, after which he is beheaded on camera. This is apparently an installment in a series of videos being posted by Mexican drugs gangs who are waging an online war of intimidation.

YouTube reportedly removed the video after it was brought to their attention and posted a notice saying it violated the site’s terms of use. YouTube’s Community Guidelines say “graphic or gratuitous violence is not allowed.”

This post is not about YouTube. It is about the legality, or illegality, of posting a snuff film – a film that premeditatedly records the murder of a human being – online. This is not an issue we have ever had to address because we – the general media-consuming public – have never encountered a snuff film. Some have claimed they don’t exist, that they’re apocryphal. I’ve always doubted that. Life is cheap enough in various corners of this and other countries that I see no reason why a snuff film could not, and would not, be made.

Publicizing one, though, is a different issue: Prior to the rise of the Internet it would neither have been possible nor intelligent to distribute a snuff film. Media outlets would not have touched it, and distributing it would only have been asking for law enforcement to go after any- and every-one involved in its creation.

Murder

Anyone involved in creating a snuff film is liable for murder. Assume the YouTube beheading video had been filmed in the U.S. and that U.S. law enforcement tracked down those involved in its creation. The person (or persons, I’ve only seen parts of the video) who actually beheaded the man is a murderer, pure and simple. In case anyone does not know, law defines murder as purposely taking the life of another human being. Case closed: The video records what happened, and even a good defense lawyer won’t be able to convince a jury that the perpetrator “accidentally” or “innocently” beheaded the victim, at least not given the descriptions I’ve seen.

What about the others . . . the people who were present, filming and otherwise assisting with the murder and with its being recorded? They, too, are liable for murder, though on a different theory.

In law, you can be liable for a crime either as a principal (the killer, in this instance) or as an accessory to a crime (murder, here). Accessories are people who either (i) facilitate the crime by, say, tying up the victim or providing materials to be used in committing it; or (ii) encourage the commission of the crime. The person or people who recorded the beheading would be liable for murder, even if this is “all” they did, because the law would find that they encouraged its commission. The level of encouragement that suffices to hold someone liable as an accomplice does not have to be, as we say in law, the but-for cause of the crime; that is, it does not have to be the cause of the crime. Law does not want people playing any role in promoting the commission of crimes, so even a pretty low level of encouragement – such as videotaping the crime with the perpetrator’s knowledge – would qualify.

Okay, these people are easy. They participated, in various ways, in the commission of the crime and therefore helped set it in motion and bring it to its culmination. That, in law and in common sense, makes them liable for what happened.

Later

But what about people who come later, after the murderhas been committed and it is too late to stop it, but who “publish” the video of the crime? Do they bear – should they bear – any criminal liability for the crime?

They did not commit the murder, so they can’t be directly liable for it. They weren’t there when it was committed, indeed, probably knew nothing about the murder until after it was committed, so they can’t be liable as accomplices. As I noted above, the premise on which we hold accomplices liable is that they contributed to the commission of a crime; you can’t contribute if you weren’t there and knew nothing about what was going on until after it had already happened.

There is a related concept called “accessory after the fact,” but that only applies to people who help a criminal escape after the criminal has committed the crime. That obviously would not apply here, since showing the crime could, at the very least, help identify the perpetrators and bring them to justice.

All of the doctrines we have that impose criminal liability only operate prospectively, that is, they only apply to conduct that occurs before a crime is committed and that either actually contributed to the commission of the crime or was intended to do so. (You can be an accomplice if you try your best to facilitate the commission of a crime, but don’t succeed . . . if, say, you show up with the murder weapon but the murderer has already left and uses a different weapon. The law says you tried, so you’re an accomplice.)

That’s only common sense. As I said above, things you do after a crime has already been committed can’t possibly have contributed to its commission.

So, if snuff films were to start showing up online (which I most certainly hope does not happen), we’d need to come up with a different theory to impose criminal liability on those who were “publishing” them . . . if, of course, we thought that was a good idea.

Policy

Do you think that’s a good idea? Do you think we should make it a crime to post snuff films online?

If a U.S. jurisdiction were to do that, the law would certainly be challenged as violating the First Amendment. I’m not going to get into First Amendment issues here, though, because I have enough to do without that.

I’m speculating about the possibility of criminalizing the online publication of a particular type of crime that has already occurred: an orchestrated, intentionally-filmed homicide. Opponents of such a law might point out that television and online news outlets show, and have shown, films of other crimes being committed and that this has never given rise to calls for criminalizing these broadcasts.

Proponents of such a law would argue that a real snuff film – even a not-for-profit snuff film like the one that just surfaced – is different. They would argue that the filming is itself an integral part of the crime being committed, that the entire purpose of a snuff film is to memorialize the act. Those who would support criminalizing the online distribution of snuff films would conclude that if we do not criminalize the distribution of snuff films we are not only playing into the filmmakers’ hands – giving them the fame or whatever else it is they wanted – we are also doing something even more harmful.

They could argue that letting these films be distributed online could encourage the production of other, similar films. That is, the proponents of criminalizing the online (or whatever) distribution of snuff films could argue that the act of “publishing” such a film can, in effect, do what accomplices do – it can encourage someone to commit a crime. Now, in this context the encouragement would not be focused on the commission of a specific crime as it has always been in the real-world; it would be a more general, global act of encouragement.

The opponents of criminalizing the distribution of snuff films could counter with the argument that this goes too far . . . that we do not, and cannot, criminalize everything that has a generalized potential to encourage someone, somewhere, to commit a crime.

This may seem an irrelevant, unnecessary train of thought, since snuff films have never publicly surfaced and have never been publicly distributed . . . at least not until that brief time period while the Mexican video was on YouTube. But one could, quite rationally, dismiss that as an aberration.

I hope it is. I like cyberspace. I like cyberspace with its variously creative, entertaining, obnoxious, disgusting, frightening, depressing, fascinating content. I, personally, don’t want to see it cut back, restrained and civilized. I will not, though, be surprised if the snuff film issue crops up again . . . and in a domestic context that makes it more difficult for us to ignore.

Much of the online content is currently being filtered in an ad hoc way to conform to certain standards of what the public is deemed to find acceptable. A few years ago, there was a furor because a U.S. website posted the video of reporter Daniel Pearl’s being beheaded. The site operator invoked the First Amendment as the reason for posting the video in an argument I, for one, could buy; this was a record of a past crime, of something we may not want to see but that had happened to an American because he was an American. There is a political context there, which I think justifies the invocation of the First Amendment.

The online filtering etiquette will probably develop cracks as things go along, and tend to degrade . . . which means we may very well see a site that hosts a snuff film, or two, or three, one of these days. If that happens, I will be curious to see how we react as individuals and how, if at all, the law reacts.

Happy Friday the 13th.

Tuesday, April 10, 2007

If a crime falls in the forest . . . ?

That vaguely Zen-ish caption is my way of launching this exploration of the possibility of using real-world law – specifically, U.S. federal law – to prosecute people who run virtual casinos in places like Second Life.

As The Register noted, this possibility raises the prospect of “virtual prosecutions” and of “virtual FBI agents kicking down virtual doors”. As The Register also noted, “the mind spins.”

The context here is that Linden Labs, operator of Second Life, has recently invited FBI agents to “take a look around” in Second Life and “raise any concerns” they may have about gambling going on there. According to a Linden Lab representative, the agents “did look around in a virtual casino” but no made no arrests.

The reason for that, of course, is it is far from clear whether gambling in Second Life, or in any other virtual would, would violate U.S. law. If it did, prosecutors and agents would then have to figure out how to enforce the law in this context, which is an issue I’ll get to in a minute. I want to start with whether virtual world-based gambling is, or should be, a crime. I’ll outline what the law is first, and then throw in my own two cents.


There are basically three federal statutes that could (emphasize “could”) be used to prosecute gambling in Second Life. One is the Travel Act, 18 U.S. Code § 1952. The Travel Act basically makes it a federal crime to travel in interstate or foreign commerce or use the mail or any facility in interstate or foreign commerce with to (i) distribute the proceeds of or (ii) otherwise “promote, manage, establish, carry on, or facilitate the promotion, management, establishment, or carrying on, of any unlawful activity”. 18 U.S. Code § 1952(a). “Unlawful activity” includes gambling that is carried on in violation of the laws of the state in which it occurs. ” 18 U.S. Code § 1952(a). So, to qualify for prosecution under this statute, gambling in a virtual casino in Second Life or in any other online world would have to violate the law of the “state in which it occurs” . . . which raises a very interesting question.


Does the gambling that goes on in Second Life occur “in” any U.S. state? Linden Labs itself is located in San Francisco. I don’t know where the Second Life servers are located, but for the sake of analysis let’s assume they are also located in California. And let’s make this analysis even easier by assuming the kind of gambling that goes on in Second Life casinos does violate California state law (again, that’s just an assumption).

Okay, let’s further assume that John Doe (our favorite person to pick on in law school) operates a casino in Second Life. Doe lives in Maine, and his customers come from various U.S. states (including California). They also come from outside the U.S., from countries where online gambling is, let’s say, either legal or has not been declared to be illegal. Can Doe be prosecuted for violating the Travel Act?

We have no indication he traveled in interstate commerce as part of operating his online casino, so that option is out. Using the Internet would qualify as using a facility in interstate or foreign commerce, so if we can say he used the Internet to carry on or facilitate the conduct of a gambling operation that violated California law, then he could, it seems, be prosecuted for violating the Travel Act. Doe, who lives in Maine where, we’ll assume, this type of gambling is not illegal, might argue that what he was doing is legal in the state where he lives . . . and, besides, he’d argue, how can anyone say that the online gambling that occurred “in” Second Life took place in California? Doe was never in California, nor where most of his customers (a few were, just to make things interesting).

That raises a very interesting issue, one that runs through a lot of legal analysis involving online activities. We’re dealing with an emergent reality here – with a virtual construct that becomes the scene of conceptual human activity as surely as the real, physical world is the scene of physical human activity. Do we treat this emergent reality as a “real” reality or do we reduce it to a physical reality? That is, do we say that the gambling going on in Doe’s casino occurred in Second Life and nowhere else . . . which would put it outside the scope of the Travel Act? Or do we say it occurred, presumably simultaneously, in California and in any other venue where one of the players was physically located?

These are very important questions because the other two federal statutes that could criminalize gambling in virtual worlds such as Second Life also require that the gambling have been illegal under the law of a U.S. state. 18 U.S. Code § 1955 & 31 U.S. Code §§ 5362(10), 5363 & 5366. So whether or not this type of online gambling can be prosecuted under current federal law depends on how we answer the questions I posed above? (Whether or not a state, such as California in this hypothetical, could prosecute will also depend on how we answer these questions.)

This is where we come to my two cents. It seems incredible to me that we would create these complex, heterogeneous online worlds and then attempt to reduce them to parochial venues. As far as I can tell (having dabbled a bit in Second Life), one reason, if not the principal reason, people participate in Second Life is to have experiences that transcend what is available to them in their localized physical reality. For that matter, many of the experiences people can have in Second Life transcend what is available to anyone in any physical reality currently existing anywhere on the globe, which makes it even more interesting.

The U.S. Supreme Court has implicitly recognized that it will have to deal with this issue in a different context – in the matter of defining what is and is not obscene. For some reason, in the U.S. we still criminalize matter that is “obscene” but do not criminalize mere “pornography.” The Supreme Court long ago articulated a test for determining whether something is obscene, a test that incorporates local community standards as one of the factors it considers.

Now, that test may have made sense when sexually-oriented material was only available in hard copy and had to be physically shipped to a location and displayed there for sale. In that world, the material itself came into the community which, at least arguably, could give the community the interest and the right to exercise some control over it.


The migration of sexually-explicit material online makes that standard changes that equation and makes that standard essentially meaningless. The material does not come into the community; the community (or those members of the community who are interested in such material) seek out this material by going online. This means that they gain access to something that is being distributed for a much wider audience – a global audience, in effect. As the Supreme Court has intimated, it is clear that relying on the community standard to define what is and is not obscene is an obsolete artifact of a different world. What made sense when New York City and Peoria (sorry, Peoria) were physically and culturally isolated makes no sense when precisely the same material and same experiences are available online to people in either city.

Obviously, I think the current federal approach to criminalizing gambling should not apply to activity in Second Life or in any other virtual world. So far I’ve based that argument simply on parsing the language of the applicable law, with a gloss added as to how we interpret when – if – virtual activity occurs “in” a physical venue.

Let’s go beyond that now and discuss a related issue: If online gambling occurs purely online, and if it only involves the use of virtual currency, what, then, is the “harm” with which the law should be concerned? I’ve never been quite clear as to what “harm” is involved in real-world gambling. The social concern seems to be to protect people from themselves, i.e., to protect people from gambling away all their money.

I don’t see why we need to be concerned with this victimless crime, when people are quite free to fritter away their money on cars, worthless real estate, jewelry, or their latest infatuation. Nor do I see how criminalizing gambling can be justified selectively; as we all probably know, in the U.S. many states conduct lotteries and/or operate casinos, which is quite legal. It’s just illegal, outside a couple of states, if private parties do that.

But let’s go with the premise that there is some justification for criminalizing gambling in the real-world because of the loss of “real” assets. The proponents of online gambling might point out that in Second Life, anyway, the gambling involves the use of Linden dollars, not U.S. dollars or any other real-world currency. They could use this to argue that whatever “harm” is involved in real-world gambling does not exist for online gambling.


The opponents of online gambling would no doubt point out that gambling in Second Life involves the use of Linden dollars which can be “exported” to the real-world. Their argument, then, would be that the same “harm” targeted by real-world gambling (whatever it is) results from online gambling because people can (I assume) move real-world currency into Second Life and use it for gambling . . . and there irresponsibly dissipate their assets. If you buy the argument for criminalizing gambling in the real-world, you’d no doubt buy that argument. If, of course, a virtual world only allowed gambling to be conducted with virtual currency that was not transportable into or from the real-world, the validity of this argument radically erodes.

Let’s still assume, for the purposes of analysis, that there is a valid reason to criminalize gambling in virtual worlds like Second Life and that we have figured out a rational way to apply federal law to this end. One logical possibility would be to quit using state law as a definitional component of the statue criminalizing online gambling and just adopt a federal statute that made online gambling a crime. There are reasons why that approach might be problematic, but while we’re hypothesizing let’s just assume that was done and it worked. This brings us to the enforcement issue.

If everything else is in place, how would federal agents enforce laws criminalizing gambling in Second Life (and similar online venues)? The obvious way to do this is to put pressure on Linden Labs to crack down on virtual casinos. Since Linden Labs is located in the United States, and since Linden Labs has a real, external presence in the territory of the United States, federal agents and prosecutors could tell Linden Labs to shut down virtual casinos in Second Life or face prosecution. The government’s theory there would be that Linden Labs was liable for aiding and abetting illegal gambling if it did not shut down the illegal virtual casinos. (The government could also argue that Linden Labs was conspiring with the operators of the virtual casinos to violate the federal law we’re assuming applies here.)

If that were to happen, I’m sure Linden Labs would comply, to the best of its ability. The problem is, as a Linden Labs representative recently pointed out, since there are millions of registered accounts in Second Life and millions of places and objects in Second Life, it simply would not be feasible for Linden Labs to be able to keep track of every virtual casino that cropped up . . . especially not if the operators took steps to conceal what they were doing.

So, what would be the solution? As
The Register said in the quote I began with, we’d presumably wind up with virtual federal agents conducting virtual undercover investigations (virtual snitches?) in Second Life. I don’t know about you, but I’m just not persuaded that we need to go there.

Friday, March 30, 2007

Vista, Backdoors and the 4th Amendment

As you may know, rumors have spread that Microsoft put a backdoor in its Vista program to accommodate law enforcement’s need to search on computers.

Microsoft denies this, which I tend to believe, but I know people who claim that it’s true. At the very least, it raises some interesting 4th amendment issues.


Let’s begin with why the backdoor issue arises.

Vista incorporates a feature called BitLocker Drive Encryption. BitLocker, which “is included in the Enterprise and Ultimate editions of Vista,” encrypts data on a computer. BitLocker Drive Encryption, Wikipedia. “By default it uses the AES encryption algorithm in CBC mode with a 128 bit key, combined with the Elephant diffuser for additional security.”
BitLocker Drive Encryption, Wikipedia. According to Microsoft, it prevents unauthorized users from gaining access to data contained on a computer: “with BitLocker all user and system files are encrypted including the swap and hibernation files.” BitLocker, Microsoft.

Users’ ability to encrypt all the files on their computer obviously poses problems for law enforcement officers who want to search a computer for evidence of a crime. But as some have noted, BitLocker should not pose problems for law enforcement in two instances:
  • One is if the computer is running; as one source notes, “forensic tools can access the encrypted volume of a running system just like any other program”. Simson Garfunkel, Drive Encryption: Two Tales, Technology Review. If the computer is running, the encryption key has already been entered into the computer, so the encryption is not an issue.
  • The other instance in which BitLocker won’t pose problems for law enforcement is when people haven’t bothered to use it.
As we probably all now, encryption is not new; encryption is available on the Mac I am using to write this, and there are programs available which can be used to encrypt data. So far, most people simply don’t bother.

Notwithstanding all this, BitLocker will still probably raise issues for law enforcement. One is how officers should proceed when they arrive to execute a computer search and the computer is running; the officers can presumably conduct a forensic analysis of the computer and thereby avoid BitLocker’s encryption, but that remains to be seen. I am not going to address that issue here. What I want to examine is the legality (or illegality) of including a backdoor on the Vista system to let law enforcement bypass encryption that has been installed on a system and that is in effect because the system has been shut down.

We will assume, for the purposes of analysis only (which means this is all purely hypothetical), that Microsoft incorporates a backdoor that lets law enforcement bypass Vista encryption. For the purposes of analysis, we will also assume that officers arrive at John Doe’s home with a warrant to search his computer for evidence of a crime (child pornography, terrorism, murder, take your pick). He lets them in, takes them to the computer, the computer is not running and they quickly find out he has implemented BitLocker. Now, BitLocker can be implemented several ways, one of which involves storing the BitLocker encryption key on a USB drive; the USB drive must be inserted into the computer for it to boot. The officers ask Doe for the USB drive they need to boot the computer; he refuses to give it to them, says he “threw it away.”

Absent a Vista backdoor, they have two and only two options at this point: They can use a grand jury subpoena or other means to “compel” Doe to surrender the key (assuming he lied when he said he threw it away), but to do this they probably will have to give him immunity for the act of handing it over. As I explained in an earlier post, immunity lets the government override his Fifth Amendment privilege, which Doe will assert as the basis for refusing to turn over the key. Doe will say, in effect, that by turning the key over he would be forced to be a witness against himself in violation of his Fifth Amendment privilege against self-incrimination.

Unfortunately, giving Doe immunity for the act of handing over the USB drive probably means they will not be able to prosecute him, since the effect of the immunity is to bar the government from using his act of handing over the drive and any evidence derived, directly or indirectly, from that act against him in a criminal prosecution. Since the evidence, if any, found on the hard drive would derive from the act of handing over the USB drive, they would be giving up the opportunity to prosecute him. The other option is to break the encryption which, I believe, would be very difficult to do.

What if, hypothetically, Microsoft had created a backdoor in Vista that would let law enforcement bypass BitLocker encryption and access the data on Doe’s computer? If Microsoft were to do this, could law enforcement then use the backdoor without violating the 4th amendment?

I don’t know of any criminal cases in which this issue has arisen. It came up last year when Michael Crooker sued Compaq (now HP) for false advertising. Crooker claimed he bought a Compaq laptop because it was advertised as having a feature – DriveLock – that secured data on its hard drive. The FBI, which had a warrant to search Crooker’s laptop, apparently found some way around the DriveLock security. In his lawsuit, Crooker claimed they used a backdoor provided by Compaq (HP). Crooker’s suit was ultimately dismissed, for whatever reason, and is irrelevant to this discussion anyway, since it did not raise any constitutional claims.

In the Doe case, the officers have a warrant to search Doe’s computer, and that allows them to access the data it contains. They, however, need outside help to access that data. There are state and federal statutes that let law enforcement obtain help from private citizens to execute search warrants; police, for example, have always needed help from phone company employees to tap landline telephone calls. The government would probably argue that the officers’ using the backdoor Microsoft installed on the system is no different from officers’ obtaining the assistance of telephone company employees to tap telephone calls. The warrant gives the officers the constitutional authority to obtain the evidence (here, the content of the calls); the telephone company employees are simply helping them to implement that authority.

The defense would argue that law enforcement’s using our hypothetical Vista backdoor to access the data on Doe’s encrypted computer is different from the scenario I outline above. How is it different? Well, one difference goes to the issue Crooker raised in his lawsuit: Doe, the defense would argue, specifically purchased a computer with Vista in order to be able to use BitLocker to secure his data from any- and every-one, including law enforcement. Doe, the defense would say, believed he could rely on the technology he purchased from Microsoft to protect his data because (in our hypothetical) he had no reason to know there was a backdoor.

The defense would then argue that by (hypothetically) installing the backdoor, Microsoft became an agent of law enforcement. As I’ve noted before, a private party can become a law enforcement agent, which means the private party’s conduct must comply with the 4th amendment. To become a law enforcement agent, the private party must act with the purpose of assisting law enforcement (which we have here) and law enforcement must encourage the party’s engaging in conduct that assists law enforcement (which we also have here). If, then, Microsoft were to install a Vista backdoor and let law enforcement use it, Microsoft would be a law enforcement agent, at least with regard to BitLocker overrides.

The government, again, would say there’s no problem here, that the same rationale used to get phone companies to tap calls applies, i.e., the search warrant justifies what law enforcement does and what Microsoft-as-hypothetical-agent-of-law-enforcement does. Somehow, though, that just doesn’t seem right to me.

It seems to me that here Microsoft is acting like a bailor, i.e., someone who has custody of another person’s property and who is legally obligated to keep it secure. Airlines are bailors for our luggage; banks are bailors for the things we put in our safe-deposit boxes, etc. Microsoft is not technically a bailor because Doe has not given his data to Microsoft to hold and keep secure. But the relationship is analogous to a bailor-bailee relationship in that Microsoft has, at least implicitly, assumed some responsibility for keeping Doe’s computer data secure. Doe, after all, bought a Vista-equipped computer because he wanted the protection provided by BitLocker; he had no idea Microsoft could and would nullify that protection when asked to do so by law enforcement.

In a sense, what Microsoft is doing in our hypothetical is consenting to the search of Doe’s computer. Doe says “no” to the officers, Microsoft says “go ahead.” If we think of the hypothetical BitLocker backdoor as a type of consent, and if we analogize Microsoft to a bailor, then the consent would not be valid for 4th amendment purposes. There’s a federal case from the 8th Circuit Court of Appeals, United States v. James, 353 F.3d 606 (2003), in which James left disks in a sealed envelope with a friend. Federal agents asked the friend to open the envelope so they could search the disks, and the friend did. The Eighth Circuit held that this violated the 4th amendment because while the friend had lawful custody of the disks, he did not have the constitutional authority to consent to the opening of the package and to the search of the disks. Seems to me Doe could make a similar argument as to the hypothetical backdoor in Vista.

All of this will probably never come up for BitLocker, since Microsoft vehemently denies putting a backdoor in Vista (and I tend to believe them). But that does not mean law will never have to confront the problem of backdoors.

Saturday, March 24, 2007

Hackback as Self-Defense

My cybercrimes students and I are discussing hackback, or strikeback, in which the victim of a cybercrime retaliates directly against her victimizer without going through the police and the legal system.

I found our discussions useful in analyzing the arguments can be made for and against hackback, so I thought I'd share them with you.


The first question, logically, is why even discuss hackback? The reason it comes up is the actual and perceived inability of law enforcement to track down, arrest and bring to justice all or even most of those who commit cybercrimes.

As I hope everyone knows, even in the real-world police cannot arrest EVERY criminal. Instead, their goal is to arrest ENOUGH criminals to keep crime under control in a society.

Modern legal systems operate on the premise that the best way to keep crime under control is to deter people from committing crimes, and the way they do that is to make enough of us believe we will get caught if we commit a crime. Getting caught is very important. Studies have shown that the perception you will get caught if you commit a crime is much more effective as a deterrent than is raising the severity of the penalty imposed on those who are caught. If, say, I think I have a 5% chance of getting caught if I steal $50 million, I may very well weigh the odds of getting caught against the benefits of committing the crime (large) against the chances of not getting caught (good), and go for it.


The problem is, as I’ve said before, that cybercrime makes the implementation of this crime control strategy incredibly difficult. Aside from anything else, cybercrime often (usually) tends to come from “outside” the jurisdiction where the victim is, and this can pose terrific problems for police trying to investigate the crime and arrest the perpetrator. Another problem is that cybercrime is added to the crime that already exists in the real-world, so police have all that extra work to do, which means they often must triage their priorities: If people are being physically harmed in the real-world, that necessarily takes priority over what happens in the virtual world because, so far anyway, cybercrime involves little if any risk of direct physical injury or death to the victims.

So, given law enforcement’s increasing inability to apprehend cybercriminals, it only makes sense that hackback – victim self-help – begins to sound appealing. It’s the same phenomenon that generates vigilante activity. (One difference between vigilante activity and hackback is that vigilantes – a la Perverted Justice – tend to affirmatively seek out perpetrators or would-be perpetrators, while hackbackers are retaliating for what was specifically done to them.)

I’ve seen postings and articles that say hackback is permissible under our existing law because it constitutes self-defense. These sources sometimes note that the right of self-defense under U.S. (and most) law can encompass the use of deadly force against an attacker, and point out that since deadly force cannot (so far, anyway) be used online, the use of retaliatory force clearly falls within the doctrine of self-defense.

The first problem I have with these views is that the scenarios involved in hackback (so far, anyway) do not involve the threat of physical injury or death to the perpetrator; they involve the threat of damage to or loss of the victim’s property, which is a very different thing.

U.S. law (and, I believe, most other legal systems) recognizes two different justifications for using force against an attacker. One is self-defense, which means exactly what is says: I can protect my physical self from an attacker who threatens me with physical injury or death.

The Model Penal Code – the set of model laws that are the template for contemporary U.S. criminal law – says, for example, that “the use of force upon . . . another person is justifiable when the actor believes that such force is immediately necessary for the purpose of protecting himself against the use of unlawful force by such other person on the present occasion.” Model Penal Code § 3.04(1). A later section of the MPC defines “unlawful force” as “force . . . that is employed without the consent of the person against whom it is directed and the employment of which constitutes an offense or actionable tort”. Model Penal Code § 3.11(1). So, under these provisions and laws based on them, I can use force to protect myself to the extent I personally believe it is necessary (no other alternative) to protect myself from someone else’s using force to harm me. The MPC limits the use of deadly force to instances in which the would-be victim believes it is necessary to protect herself “against death, serious bodily injury, kidnapping or sexual intercourse compelled by force or threat”. Model Penal Code § 3.04(2)(b).

I do not see how these standards can apply online. The “force” that is used online is directed at things, not people. It is true that online activity can become the vector that is used to set a real-world physical attack in motion: A cyberstalker can use online postings and the manipulation of online information to try to persuade a naĂŻf who likes to play sado-masochistic sexual games to attack the person the stalker is trying to set up, but the attack – and the victim’s use of defensive force, if any – all occur in the real-world.

Unless and until we acquire the capacity to directly cause physical injury to one another via cyberspace, hackback is really about a very different problem: defending property. U.S. law (and law in many other countries) lets people use force to defend their property, but only within limits.

Let’s go back to the Model Penal Code. Section 3.06 of the MPC says that you can use force “upon or toward the person of another” when you believe the use of such force “is immediately necessary . . . to prevent or terminate an unlawful entry or other trespass upon land or a trespass against or the unlawful carrying away of tangible, movable property” belonging to you. Model Penal Code § 3.06(1)(a). Under this provision, you can only use non-deadly force, i.e., force that is not likely to cause death or serious bodily injury. You can only use deadly force to protect property if (i) the attacker is trying to “dispossess” you of your “dwelling” or (ii) the attacker “is attempting to commit . . . arson, burglary, robbery or other felonious theft or property destruction” and has either used or threatened to use deadly force or the use of less than deadly force would expose you to a risk of death of serious bodily harm. The last option, of course, brings in self-defense. Model Penal Code § 3.06(3)(d).

So, how can we apply this to hackback? Would hacking back against someone who had unlawfully accessed your computer/data or infected your system with a virus or launched a DDoS attack on your website be a valid use of force to defend your property?

It doesn’t seem to me that these scenarios or any I can think of at the moment would qualify as “dispossessing” you from your “dwelling” . . . unless and until we decide that the computer system you use if your “dwelling.” I think that would be way too much of a stretch for the drafters of the MPC or for modern legislators, so we’ll give up on that option.

Unauthorized access to a computer system for the purposes of committing a crime (such as destroying or copying data) clearly qualifies as burglary. I can’t think of any online misconduct that would qualify as arson, so we’ll give that a pass. Robbery is using force to steal someone’s property; if we read “force” as “physical force,” this option would not seem to apply online, either. Clearly, though, spreading malware could qualify as the attempted (and consummated) destruction of property, so it falls within the traditional defense of using force to protect one’s property. I think a DDoS attack can also qualify as a destruction/attempted destruction of property if, of course, we broaden our concept of property a bit, to include lost business opportunities and costs incurred in dealing with such an attack.

One problem we do have with applying laws like the MPC provisions described above to hackback is the notion of “property.” If you look back at the MPC defensive use of force to protect property provision I quoted above, it only lets you use force to protect “tangible, movable property.” Data is certainly movable, but we’d have to qualify it as “tangible” property for this provision to apply to online attacks; the drafters of the MPC most certainly were not thinking of intangible property like data when they wrote this provision, but if we could convince legislators to broaden the scope of self-defense statutes, that would not be a problem.

It seems, then, that we can apply the “defense of property” doctrine to hackback, at least in certain instances and with certain modifications to the traditional doctrine. The one condition a hackback-er would have to meet in order to invoke this defense is the issue noted above, i.e., that the use of defensive force was “immediately necessary.” This means the hackback-er had no other alternatives but self-help; and what that generally means is that it would have been futile for the hackback-er to have taken the usual route and contacted law enforcement. The “defense of property” doctrine is really meant to apply to instances in which there is a face-to-face confrontation between a perpetrator and a would-be victim that makes it impossible, or dangerous, for the potential victim to try to call police. The “immediately necessary” element means the victim had to act at that moment or face the loss of her property.

That element might not be a problem for some instances of hackback . . . instances in which the hackback-er interrupted a perpetrator who was in the process of carrying out an attack. That scenario conforms more closely to the scenario the defense of property doctrine was intended to encompass. Applying the doctrine becomes much more difficult if the hackback occurs well after the attack has been completed and the damage has been inflicted. That starts to look a lot more like simple retaliation – hitting back to punish someone who has already hurt you – than the defense of property doctrine. The rules governing the defensive use of force all assume the victim is trying to prevent or minimize the infliction of “harm” in an ongoing, volatile situation. They do not sanction cold-blooded revenge.

There are other problems with applying the laws governing the defensive use of force to hackback, one being the accuracy of the response. That tends to be less of a problem for real-world scenarios than for online attacks because, as I just noted, in real-world attacks the attacker and victim are face-to-face. The victim may err in estimating the need to use force (and the level of force used), but the victim is usually accurate in deciding whom the force should be used against. As I assume we all know, this is not true online; attacks can be vectored through computers in many locations, so if we were to sanction hackback we would either have to incorporate an “accurate identification of the perpetrator” element or limit it to confrontations arising from attacks in progress.

Since this post is already long, I’ll take up that issue and a related issue (automating hackbacks) another time.

Thursday, March 22, 2007

To Catch a Predator . . . Must There Be Prey?

We’re probably all familiar with the NBC Dateline “To Catch a Predator” programs.

In these Dateline episodes, reporter Chris Hansen films interviews with men who have shown up at a location intending to have sex with what they believe is a minor male or female.


The men are the targets of a “sting” operation. They've actually been chatting online with someone from the group Perverted Justice.

As one court noted, Perverted Justice “is an organization dedicated to exposing child molesters” which NBC pays for its contributions to the Dateline episodes. (United States v. Kaye, 451 F. Supp.2d 775 (E.D. Va. 2006)).

The Dateline-Perverted Justice collaboration is just one, isolated instance of a “sting” model that has become popular in the United States. Police officers in jurisdictions all over the country (including one police department in a city about 30 miles from where I am writing this) go online and pretend to be barely adolescent females or males. The purpose is to identify pedophiles who will try to lure the children to a meeting for the purposes of having sex. I have spoken to officers who have run stings like these, and they tell me “it’s shooting fish in a barrel,” i.e., that once they go into an appropriate chat room pretending to be barely-pubescent “Melissa” or “Heather,” the pedophiles pounce almost immediately.

The defendants in these cases will be prosecuted for what they have done. The charge, which takes slightly different forms in various states and at the federal level, is “luring” or enticing a child into a sexual rendezvous. I just read a relatively recent decision from a Virginia federal district court in which the defendant used a common argument in an effort to have the charges against him dismissed. (United States v. Kaye, 451 F. Supp.2d 775 (E.D. Va. 2006)).

This defendant, like many before him, argued that the charges against him should be dismissed because there was no child. That is, he said he was charged with luring or enticing a “child” into a sexual rendezvous, but the online chats he had were not with a child; they were with an adult representative of Perverted Justice. He argued, therefore, that the charges could not stand because no child was involved in what he did, and no child was ever in any danger of being sexually exploited.

That is a logical argument, and has succeeded on occasion, especially under older statutes which actually require that there have been a “child.” It fails, though, when the charges are brought (i) under a statute which makes the act of luring or enticing a child to a sexual rendezvous a crime in and of itself or (ii) under a provision which makes it a crime to attempt to lure or entice a child to a sexual rendezvous. Neither of these offenses requires that there have actually been a child victim. They focus on what the defendant intended to do, so if the evidence shows that the defendant believed he was corresponding with a child and if the defendant used that correspondence to entice what he truly believed was a child to a sexual rendezvous, then the defendant has committed this crime. It is irrelevant that he was actually corresponding with, say, a 45 year old male detective or a 30 year old female representative of Perverted Justice.

You might wonder why the law finds it necessary to adopt statutes which criminalize conduct that is impossible, which is the case here. As Kaye argued in the case I cited above, based on the facts involved in that instance it was both “factually and legally impossible” for him ever to have actually had sex with a minor, more precisely, with the minor male he apparently believed he was corresponding with. And Kaye is right; these statutes do criminalize conduct that is, at least in the contexts of these stings, totally impossible.

Why do that? The rationale is based in what the law calls inchoate, or incomplete, crimes. Attempt is an inchoate crime; it criminalizes unconsummated efforts toward the commission of a crime. So, say the FBI has learned that John Doe intends to rob the First National Bank. The FBI observes Doe as he “cases” the bank and makes other preparations and tracks him as he heads to the bank on the day he intends to commit the crime. FBI agents arrest him outside the bank before he is even able to begin the process of robbing it. Doe will be charged with attempting to rob the bank; he cannot be charged with robbing the bank because he never got the chance to do that.

The law criminalizes attempts on the theory that it protects public safety. If we did not criminalize attempts, the FBI would have to wait for Doe to rob the bank and then try to arrest him afterward. Aside from letting him take money that is not his, this could also expose people in the bank to the risk of death or serious injury if something went wrong in the robbery or if Doe simply became trigger-happy. The law says it is better to have a repertoire of inchoate offenses – like attempt in this scenario and like the luring or enticing offenses I noted above – to let law enforcement intervene and head off crime before it occurs.

Now, some claim that stings like those the Dateline crew films go too far . . . that they essentially represent the manufacture of a crime. Those who make this argument would say that the people, like Kaye, who are caught in the luring and enticing stings are not like Doe because they had not independently embarked on a course of criminal conduct. The critics of these stings say that law enforcement has played a much more active role in creating these crimes than in the bank robbery scenario I outlined above.

Advocates of the stings say they are taking a pro-active approach to protecting children, and that every sting represents the interception of what could have been a real crime.

Wednesday, March 21, 2007

Employees, Employers and the Fourth Amendment

I recently heard from someone whose employer searched his office computer and used the information obtained from it against him in a civil suit.

He asked if this violated the Fourth Amendment. The answer, basically, is “almost certainly not” . . . and I want to try to explain WHY that is the answer.
To do that, I’m going to use a recent decision from the Ninth Circuit Court of Appeals: United States v. Ziegler, 474 F.3d 1184 (9th Cir. 2007).


Here are the facts as the court described them:

"On January 30, 2001, Anthony Cochenour, the owner of Frontline [Processing's] Internet-service provider . . . contacted Special Agent James A. Kennedy, Jr. of the FBI with a tip that a Frontline employee had accessed child-pornographic websites from a workplace computer. Kennedy pursued the report . . . , first contacting Frontline's Internet Technology Administrator, John Softich. One of Softich's duties . . . was to monitor employee use of the workplace computers including their Internet access. He informed Kennedy that the company had in place a firewall, which permitted constant monitoring of the employees' Internet activities. . . .

"Softich confirmed . . . that a Frontline employee had accessed child pornography via the Internet. . . . . Softich further informed Kennedy that, according to the Internet Protocol address and log-in information, the offending sites were accessed from a computer in the office of . . . Ziegler, who had been employed by Frontline as director of operations since August 2000. Softich also informed Kennedy that the IT department had already placed a monitor on Ziegler's computer to record its Internet traffic by copying its cache files.

"Kennedy next interviewed William Schneider, Softich's subordinate . . . Schneider confirmed that the IT department had placed a device in Ziegler's computer that would record his Internet activity. He . . . had `spot checked' Ziegler's cache files and uncovered . . . child pornography. A review of Ziegler's `search engine cache information' also disclosed that he had searched for “things like ‘preteen girls' and ‘underage girls.’ Furthermore, according to Schneider, Frontline owned and routinely monitored all workplace computers. The employees were aware of the IT department's monitoring capabilities. . . .

"According to . . . Softich and Schneider . . . Kennedy instructed them to make a copy of Ziegler's hard drive because he feared it might be tampered with before the FBI could make an arrest. Kennedy, however, denied that he directed the Frontline employees to do anything. . . . [H]is notes say, `IT Dept has backed up JZ's hard drive to protect info.' Kennedy testified that he instructed Softich only to ensure that no one could tamper with the backup copy.Whatever Agent Kennedy's actual instructions, . . . [a]round 10:00 p.m., Softich and Schneider obtained a key to Ziegler's private office . . . , entered Ziegler's office, opened his computer's outer casing, and made two copies of the hard drive.


"Shortly thereafter, Michael Freeman, Frontline's corporate counsel, contacted Kennedy and informed him that Frontline would cooperate fully in the investigation. Freeman indicated that the company would voluntarily turn over Ziegler's computer to the . . . . On February 5, Reavis delivered Ziegler's computer tower (containing the original hard drive) and one of the hard drive copies. . . .. Schneider delivered the second copy sometime later. Forensic examiners at the FBI discovered many images of child pornography."

United States v. Ziegler, supra. Ziegler was indicted for possession of child pornography and moved to suppress the evidence against him.

Ziegler argued that Agent Kennedy violated the Fourth Amendment by “directing” the Frontline employees to search Ziegler’s office and computer. So, Ziegler was claiming that the Frontline employees had become agents of the government, which he had to do to invoke the Fourth Amendment. The Fourth Amendment only protects us from action by the government; if a private citizen decides to search your home or office and takes what she finds there to the police, you are out of luck, as far as the Fourth Amendment goes. You can try suing the private citizen who searched your home or office for trespass or invasion of privacy or some other civil cause of action, but you have absolutely no claim under the Fourth Amendment . . . as long as the person was acting on their own.

This was Ziegler’s argument. He claimed, and the Ninth Circuit agreed, that he had a valid Fourth Amendment expectation of privacy in his office. The court noted, among other things, that the facts his computer was password-protected and his office had a lock on the door established this.

The Ninth Circuit then found that Softich and Schneider were “acting as de facto government agents,” that is, they searched Ziegler’s office because they wanted to help the FBI with its investigation, not for reasons associated with their employment by Frontline. The court also found that the government had encouraged them to do this, so that makes Softich and Schneider government agents and means their conduct has to have complied with the requirements of the Fourth Amendment, i.e., that they search of Ziegler’s office and seizure of data from his computer had to be “reasonable.”

Searches and seizures can be “reasonable” under the Fourth Amendment if (a) they are conducted pursuant to a search warrant (which was not true here) or (b) they are conducted pursuant to a valid exception to the warrant requirement, such as consent. The Ninth Circuit found that Frontline had the authority to consent to the search of Ziegler’s computer.

That authority derived from the fact that Frontline and its employees had common authority over Ziegler’s office and computer. Basically, Frontline had common authority over both because it had a key to the office and had the capacity to access his computer, notwithstanding the password Ziegler used. As the Ninth Circuit explained, while "use of each Frontline computer was subject to an individual log-in, Schneider and other IT-department employees `had complete administrative access to anybody's machine.' The company had also installed a firewall, . . .`a program that monitors Internet traffic ... from within the organization to make sure nobody is visiting any sites that might be unprofessional.' Monitoring was routine, and the IT department reviewed the log created by the firewall `[o]n a regular basis' . . . . Finally, upon their hiring, Frontline employees were apprised of the company's monitoring efforts through training and an employment manual, and they were told that the computers were company-owned and not to be used for activities of a personal nature." United States v. Ziegler, supra.

So Ziegler lost on his motion to suppress and will have to serve time for possessing child pornography.

This, I hope, illustrates why it is so difficult for employees of private companies to invoke the Fourth Amendment when their employer searches their computer. Unless the company has policies which explicitly state that the employee can use the computer for private purposes and that the company will not monitor the employee’s computer activity or otherwise investigate the contents of his or her computer, the company can, as Frontline did, consent to law enforcement’s searching the computer. And if the company itself does so for its own, private purposes, the Fourth Amendment is not implicated because there is no state action – the company is not acting for the state or federal government.